Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

641 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)1.1%—Zohocorp Zoho CRM Lead Magnet5/10/202117/6/2026
A Cross-Site Scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user’s browser while the browser is connected to a trusted website. The attack targets your application's users and not the application itself while using your application as the attack's vehicle. The XSS payload executes whenever…
ModificadaCrítica (9.8)80%—Zohocorp Manageengine Opmanager30/9/202117/6/2026
Zoho ManageEngine OpManager version 125466 and below is vulnerable to SQL Injection in the getReportData API.
ModificadaAlta (7.5)3.2%—Zohocorp Manageengine Remote Access Plus30/9/202117/6/2026
Zoho ManageEngine Remote Access Plus before 10.1.2121.1 relies on the application's build number to calculate a certain encryption key.
ModificadaAlta (7.5)4.7%—Zohocorp Manageengine Remote Access Plus30/9/202117/6/2026
Zoho ManageEngine Remote Access Plus before 10.1.2121.1 has hardcoded credentials associated with resetPWD.xml.
ModificadaAlta (7.5)4.7%—Zohocorp Manageengine Remote Access Plus30/9/202117/6/2026
Zoho ManageEngine Remote Access Plus before 10.1.2121.1 has hardcoded credentials for read-only access. The credentials are in the source code that corresponds to the DCBackupRestore JAR archive.
ModificadaCrítica (9.8)9.5%—Zohocorp Manageengine Admanager Plus27/9/202117/6/2026
Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to unrestricted file upload, leading to remote code execution.
ModificadaCrítica (9.8)93%—Zohocorp Manageengine Admanager Plus27/9/202117/6/2026
Zoho ManageEngine ADManager Plus before 7111 is vulnerable to unrestricted file which leads to Remote code execution.
ModificadaCrítica (9.8)2.2%—Zohocorp Manageengine Admanager Plus22/9/202117/6/2026
Zoho ManageEngine ADManager Plus version 7110 and prior allows account takeover via SSO.
ModificadaCrítica (9.8)10%—Zohocorp Manageengine Admanager Plus22/9/202117/6/2026
Zoho ManageEngine ADManager Plus version 7110 and prior has a Post-Auth OS command injection vulnerability.
ModificadaAlta (8.8)2.7%—Zohocorp Manageengine Admanager Plus21/9/202117/6/2026
ManageEngine ADManager Plus before 7111 has Pre-authentication RCE vulnerabilities.
ModificadaCrítica (9.8)4.8%—Zohocorp Manageengine Admanager Plus21/9/202117/6/2026
ManageEngine ADSelfService Plus before 6112 is vulnerable to domain user account takeover.
ModificadaMedia (6.5)1.9%—Zohocorp Manageengine Admanager Plus21/9/202117/6/2026
Zoho ManageEngine ADSelfService Plus before 6112 is vulnerable to mail spoofing.
ModificadaAlta (7.5)2.5%—Zohocorp Manageengine Admanager Plus21/9/202117/6/2026
Zoho ManageEngine ADSelfService Plus before 6112 is vulnerable to SSRF.
ModificadaCrítica (9.8)3.4%—Zohocorp Manageengine Adselfservice Plus10/9/202117/6/2026
Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to SQL Injection while linking the databases.
ModificadaCrítica (9.8)2.8%—Zohocorp Manageengine Adselfservice Plus10/9/202117/6/2026
Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to linked applications takeover.
ModificadaAlta (7.5)5.5%—Zohocorp Manageengine Desktop Central10/9/202117/6/2026
Zoho ManageEngine DesktopCentral before 10.0.709 allows anyone to get a valid user's APIKEY without authentication.
AnalizadaCrítica (9.8)99%⚠ Explotación activa💥 ExploitZohocorp Manageengine Adselfservice Plus7/9/202117/6/2026
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution.
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitZohocorp Manageengine Servicedesk Plus1/9/202117/6/2026
Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication.
ModificadaCrítica (9.8)2.5%—Zohocorp Manageengine Adselfservice Plus30/8/202117/6/2026
Zoho ManageEngine ADSelfService Plus 6103 and prior is vulnerable to admin portal access-restriction bypass.
ModificadaCrítica (9.8)4.8%—Zohocorp Manageengine Adselfservice Plus30/8/202117/6/2026
Zoho ManageEngine ADSelfService Plus version 6103 and prior allows CAPTCHA bypass due to improper parameter validation.
ModificadaMedia (6.1)2.9%💥 ExploitZohocorp Manageengine Adselfservice Plus30/8/202117/6/2026
Zoho ManageEngine ADSelfService Plus version 6103 and prior is vulnerable to reflected XSS on the loadframe page.
ModificadaCrítica (9.8)18%—Zohocorp Manageengine Adselfservice Plus30/8/202117/6/2026
Zoho ManageEngine ADSelfService Plus through 6102 allows unauthenticated remote code execution in non-English editions.
ModificadaMedia (6.1)0.82%—Zohocorp Manageengine Log36029/8/202117/6/2026
Zoho ManageEngine Log360 before Build 5224 allows stored XSS via the LOGO_PATH key value in the logon settings.
ModificadaCrítica (9.8)4.6%—Zohocorp Manageengine Log36029/8/202117/6/2026
Zoho ManageEngine Log360 before Build 5225 allows remote code execution via BCP file overwrite.
ModificadaMedia (6.1)0.82%—Zohocorp Manageengine Log36029/8/202117/6/2026
Zoho ManageEngine Log360 before Build 5225 allows stored XSS.
Orbitaley — Vulnerabilidades